Security

JWT Risk Analyzer

A JWT risk analyzer decodes a JSON Web Token in your browser and checks it against the mistakes that break token security: an unsigned alg of none, header-driven key injection, no expiry, and secrets or personal data sitting in a payload that anyone can read.

Last reviewed by the Radiatus Cloud team

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

What it inspects

The token is split on its two dots and each part is base64url-decoded locally. Base64url is decoded correctly here (hyphen to plus, underscore to slash, padding restored), which matters because a token that uses those characters fails a plain atob() call, the bug that made the previous version throw on real tokens.

The checks and why each is a risk

  • alg: none is critical: the token is unsigned, so anyone can forge one. Verifiers must reject it explicitly.
  • jku or x5u in the header is high risk: these point at a URL the verifier may fetch keys from. If the server trusts that URL, an attacker supplies their own key set.
  • kid with path or quote characters is the classic key-ID injection into a file path or SQL query.
  • exp above 1e12 means the expiry is in milliseconds; JWT timestamps are seconds, so the token is valid for tens of thousands of years.
  • Lifetime over 30 days, or a missing exp, aud or iss claim, each weakens replay protection.
  • email, phone, address, password or secret in the payload: a JWT is signed, not encrypted, so every claim is readable by anyone holding the token, and tokens end up in logs and browser storage.

What it does not do

It cannot verify the signature, because that needs the secret or public key, and it does not tell you whether HS256 was implemented with a strong key. Use it to read a token and catch structural problems; use jwt-decoder for a clean decode and your server logs to confirm the algorithm is pinned.

HS256 versus RS256

The analyzer notes when a token uses asymmetric RS256 or ES256, because those systems must pin the algorithm: a verifier that accepts whatever the header claims can be fed an HS256 token signed with the RSA public key, a well-documented bypass.

Related tools

  • JWT Decoder — Decode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.
  • JWT Generator — Create a signed HS256 JWT from a JSON payload and a secret, using the Web Crypto API in your browser. Nothing is sent anywhere.
  • HMAC Generator — Generate HMAC signatures with SHA-256 and other algorithms, and use them correctly.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.

Frequently Asked Questions

Does the token leave my browser?

No. Decoding and all checks run in JavaScript on the page. You can paste production tokens, though the safest habit is to use expired or test tokens.

Can it tell me if the signature is valid?

No. Signature verification needs the signing secret (HS256) or the public key (RS256/ES256), which the tool does not have. It reads the header and payload and flags structural risks only.

Why is personal data in a JWT a problem if the token is signed?

Signing proves the token was not altered; it does not hide the contents. The payload is base64url, not encryption, so anyone who intercepts or logs the token reads every claim in plain text.

What is the alg:none attack?

Some libraries historically accepted a token whose header says the algorithm is none, treating it as validly signed with an empty signature. An attacker sets alg to none, writes any payload, and is trusted. Verifiers must reject none outright.

My exp is a 13-digit number. Is that wrong?

Yes. JWT exp, iat and nbf are Unix seconds, which are 10 digits until the year 2286. A 13-digit value is milliseconds and makes the token effectively never expire.

Privacy & Security

Tokens checked locally.

Data: None
Client-side-Side
Active
v1.0

About This Tool

This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.